CVE-2019-12497

Severity CVSS v4.0:
Pending analysis
Type:
CWE-200 Information Leak / Disclosure
Publication date:
17/06/2019
Last modified:
31/08/2023

Description

An issue was discovered in Open Ticket Request System (OTRS) 7.0.x through 7.0.8, Community Edition 6.0.x through 6.0.19, and Community Edition 5.0.x through 5.0.36. In the customer or external frontend, personal information of agents (e.g., Name and mail address) can be disclosed in external notes.

Vulnerable products and versions

CPE From Up to
cpe:2.3:a:otrs:otrs:*:*:*:*:*:*:*:* 5.0.0 (including) 5.0.36 (including)
cpe:2.3:a:otrs:otrs:*:*:*:*:*:*:*:* 6.0.0 (including) 6.0.19 (including)
cpe:2.3:a:otrs:otrs:*:*:*:*:*:*:*:* 7.0.0 (including) 7.0.8 (including)
cpe:2.3:o:debian:debian_linux:8.0:*:*:*:*:*:*:*